Fam security engineer intern Bengaluru 2026 — on-site, apply on Lever
Fam (previously FamPay)
- Location
- Bengaluru (on-site, Fam HQ)
- Last date
- 31 Dec 2026
- Qualification
- Student profile with OWASP Top 10 (web and mobile), Burp Suite / Nmap / similar tools, and ability to read Python, Go, Java or JavaScript. Degree name is not printed.
- Age limit
- Not printed on the Lever card
- Vacancies
- Not numbered on the card
- Pay / stipend
- Competitive stipend printed; rupee amount not printed
- Experience
- CTF, bug bounty, or HackTheBox / TryHackMe rank expected; no year count printed
- Application fee
- None printed
- Selection
- Apply on the Lever card and complete the Fam CTF at ctf.fampay.co
Official Details
Fam security engineer intern Bengaluru 2026 is the live Application Security Engineer Intern card on Fam’s official Lever board. Location printed: Bengaluru, on-site at Fam HQ. Apply on jobs.lever.co/fampay. The card also asks you to finish the challenge at ctf.fampay.co. No advertisement number and no last date are printed. This page was checked on 1 October 2026 while the apply button was still on the card.
What Fam actually does
Fam, previously FamPay, is a private payments company. The card says FamApp is a payments app for people above 11, with UPI and FamCard, and that the company was founded in 2019 by IIT Roorkee alumni. Investors named on the card include Elevation Capital, Y Combinator, Peak XV (Sequoia Capital) India, Venture Highway, Global Founders Capital, and angels including Kunal Shah and Amrish Rao. This is not a government internship and not the Prime Minister’s Internship Scheme.
A private internship means the company writes the rules. There is no gazette, no category roster, and no application fee slab. If someone on WhatsApp asks for a “Fam registration charge”, that is not this card.
What kind of role this Fam security engineer intern Bengaluru 2026 seat is
The title on the card is Security Engineer Intern. The body calls it an Application Security Engineer Intern. Department is Engineering. Type is Full Time. Work mode is On-site. The note on the card says this is an onsite internship at Fam HQ, Bangalore. Duration in weeks or months is not printed. Bond is not printed. A full-time offer after the internship is not printed.
Work printed on the card: vulnerability assessment and penetration testing on web apps, Android/iOS apps and APIs; help integrate SAST/DAST into CI/CD; review source code for SQLi, XSS and IDOR; triage bug-bounty reports; threat modelling with product and engineering; stay current with CVEs and zero-days.
Who should apply — and who should skip
Apply if you can explain the OWASP Top 10 for web and mobile, you have used Burp Suite, Metasploit, Nmap, Postman or similar tools, you can read Python, Go, Java or JavaScript and write small scripts, and you already do CTFs, bug bounties, or ranked practice on HackTheBox or TryHackMe. You must be able to work from the Bengaluru office.
Skip if you want a remote seat, if you only know theory and have never opened Burp, or if you cannot explain a bug to a developer in plain language. Bonus points on the card, not must-haves: AWS or GCP cloud security, a hall-of-fame mention on a company bug bounty, open-source security work. Degree name, CGPA, year of study and age are not printed. Do not invent them.
Dates and fee
| Item | On the official Lever card |
|---|---|
| Apply start | Not printed. Card was live on 1 October 2026 |
| Last date | Not printed. Apply while the Lever apply button is up |
| Duration | Not printed |
| Fee | None printed. Do not pay a third party |
| Stipend | Word used is “competitive stipend”. Rupee figure not printed |
| Other printed perks | Certificate, letter of recommendation, leave policy, Fam merchandise |
| Extra step | Complete https://ctf.fampay.co/ |
Available positions
1. Security Engineer Intern — competitive stipend, rupee amount not printed Seat count not printed
Eligibility criteria
Hacker mindset with a deep understanding of the OWASP Top 10 (web and mobile) and how to exploit and patch them. Hands-on experience with Burp Suite, Metasploit, Nmap, Postman or similar open-source security tools. Ability to read code in Python, Go, Java or JavaScript and write scripts to automate attacks or defences. Active participation in CTFs, bug bounties, or a rank on HackTheBox or TryHackMe. Ability to explain a complex vulnerability to a developer. On-site at Fam HQ, Bangalore. Bonus: cloud security on AWS or GCP, a hall-of-fame bug-bounty mention, open-source security contributions.
No category-wise vacancy split is printed on this notice.
Total vacancies — not numbered on the card.
Educational qualifications
| Post | Degree / marks | Experience / extras |
|---|---|---|
| Security Engineer Intern | Degree, branch, year and marks are not printed | OWASP Top 10, Burp Suite or similar, readable code in Python/Go/Java/JavaScript, CTF or bounty practice, on-site Bengaluru, CTF challenge link |
Selection
- Open the official Lever card and apply. The card says AI tools may help review applications, but final hiring decisions are made by humans.
- Complete the challenge printed on the card: https://ctf.fampay.co/
- Further interview rounds are not printed. Do not treat a coaching-site “3 rounds” claim as official.
How to prepare (free, official)
- This Fam Lever card
- Fam CTF named on the card
- OWASP Top 10 — the list the card names
How to apply without getting played
- Open only the Lever URL above. Fam will not ask you to pay to “lock” a slot.
- Attach a resume that shows one real CTF write-up, bounty report, or lab rank. The card is looking for that, not a generic “interested in cybersecurity” line.
- Finish ctf.fampay.co before you assume the form alone is enough. The card prints both steps.
- Save the Lever confirmation. There is no fee receipt because no fee is printed.
FAQs
What is the last date?
Not printed on the Fam Lever card. Apply while the apply button is live. Checked 1 October 2026.
Who can apply?
Someone who can work on-site in Bengaluru, knows OWASP Top 10, has used tools such as Burp Suite, can read Python, Go, Java or JavaScript, and already does CTFs or bounties. Degree line is not printed.
How many vacancies?
Not numbered on the card.
Where do I apply?
jobs.lever.co/fampay, plus the CTF at ctf.fampay.co.
What is the fee?
None printed. Stipend is described as competitive. The rupee amount is not printed, so do not quote a number from a reel.
Can final-year students apply?
The notice does not say final-year. It does not print age, degree or year. On-site Bengaluru and the skill list are the filters that are printed.
internships · jobs · admissions.
Applicant Safety
Always verify notices on the official institutional website. Campus Reality only lists public notifications.
- Double-check deadlines.
- Never pay fees through unverified third-party links.
- Read the official PDF carefully before applying.